At the same time, ClamAV has a terrifying CVE track record.
There's no upside, and all downside.
ClamAV: https://www.cvedetails.com/product/15657/Clamav-Clamav.html?...
Norton AV: https://www.cvedetails.com/product/398/Symantec-Norton-Antiv...
Windows Defender: https://www.cvedetails.com/product/9767/Microsoft-Windows-De...
It may be safer to say that the CVE record for most AV software isn't great.
Given that, a possible upside with ClamAV could be that you could verify the behaviour of the processes on the installed systems, to make sure you're up-to-date and have the correct software and signatures installed.
That's not unreasonable - Microsoft's software delivery pipeline should be trustworthy and their security reputation could be damaged if an issue were discovered here.
That’s true of everything installed on a system - if you don’t control the software you’re running, Defender is the least of your worries. Unless you’re doing a full analysis of every binary you’re trusting the source.
Also I'm guessing it's easier for admins of mixed infra to have a single threat definition (ie. So your storage server catches the same threats as your endpoints)
5.1 Deploy anti-virus software on all systems commonly affected by malicious software (particularly personal computers and servers).
It's typically an ignorant CISO/CSO who wants to mark a checkbox...
Easier just to say "AV on everything".
We’re in the middle of adopting HiTrust and I’ve been forced to install Cisco AMP on all of my servers. The product is absolute garbage and frequently eats up all available RAM, causing itself to crash and leave a core dump filling up my root partition.
The worst part? AMP on Linux is literally ClamAV plus a kernel module to monitor file access, network connections and process creation.